SCCM log files enumeration
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
Detector Tags
Microsoft SCCM Analytics
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Log Enumeration (T1654)
Severity
Informational
Description
Multiple local SCCM logs were accessed within a short period of time.
Attacker's Goals
Enumerate data about the SCCM configuration, infrastructure and deployments.
Investigative actions
Check suspicious network connections from the process or host.
Check if the user account that initiated the enumeration is supposed to access these files.
Variations
PreviousSaaS suspicious external domain user activity
NextScheduled Task hidden by registry modification
Was this helpful?
